=====================
= End-of-Day report =
=====================
Timeframe: Freitag 03-07-2026 18:00 − Montag 06-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Sicherheitswarnungen: Node.js will KI-Flut mit KI bekämpfen ∗∗∗
---------------------------------------------
In der Node.js-Community ist eine Diskussion darüber entstanden, wie sie weiter mit der Vielzahl an LLM-generierten Sicherheitsmeldungen verfahren soll.
---------------------------------------------
https://www.heise.de/news/Sicherheitswarnungen-Node-js-will-KI-Flut-mit-KI-…
∗∗∗ WhatsApp-Benutzernamen wecken Befürchtungen an möglichem Identitätsdiebstahl ∗∗∗
---------------------------------------------
Betrüger könnten WhatsApp-Benutzernamen bekannter Personen zu kriminellen Zwecken missbrauchen, warnen Sicherheitsexperten. Reservierungen sind bereits möglich.
---------------------------------------------
https://heise.de/-11354304
∗∗∗ When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website ∗∗∗
---------------------------------------------
The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.
---------------------------------------------
https://securelist.com/microsoft-device-code-phishing-attack/120350/
∗∗∗ SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing ∗∗∗
---------------------------------------------
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped past every scanner tested more than 90% of the time, and the same team built a runtime checker that catches most of the disguised skills the scanners miss.
---------------------------------------------
https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.h…
∗∗∗ Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages ∗∗∗
---------------------------------------------
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits.In a proof of concept, they reconstructed a signed-in users full Gmail address from a single visit, with no click. [..] The fix shipped in Opera GX version 130.0.5847.89, so anyone on a current build is already covered; you can confirm yours at opera://about. There is no CVE.
---------------------------------------------
https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.ht…
∗∗∗ PDF-Abo-Falle: Wenn aus 99 Cent ein teures Abo wird ∗∗∗
---------------------------------------------
Wer eine PDF-Datei schnell online bearbeiten möchte, stößt auf zahlreiche Dienste, die kostenlos oder besonders günstig wirken. Nach der Bearbeitung wird häufig lediglich ein kleiner Betrag von 99 Cent für den Download verlangt. Was viele nicht bemerken: Im Hintergrund wird oft ein teures Abo abgeschlossen.
---------------------------------------------
https://www.watchlist-internet.at/news/pdf-abo-falle/
∗∗∗ AI Used in Ransomware Attack ∗∗∗
---------------------------------------------
Using AI to automate part or all of the attack chain is also more of an evolution than a revolution in ransomware. [..] Nevertheless, the attack shows how the use of AI can lead to faster, if still unsophisticated, attacks that give victims less time to react.
---------------------------------------------
https://www.truesec.com/hub/blog/ai-used-in-ransomware-attack
=====================
= Vulnerabilities =
=====================
∗∗∗ OPNsense-Update beseitigt kritische Rootlücke und weitere Sicherheitsrisiken ∗∗∗
---------------------------------------------
Die kürzlich erschienenen Versionen 26.1.11 und 26.4.1(p1) von OPNsense, einer quelloffenen Firewall- und Routing-Plattform auf FreeBSD-Basis, bringen Sicherheitsfixes mit. Unter den geschlossenen Lücken befindet sich auch eine kritische: CVE-2026-57155 (CVSS-Score 9.9 von 10.0) hätte unter bestimmten Voraussetzungen zur Rechteausweitung und letztlich zur kompletten Firewall-Übernahme missbraucht werden können.
---------------------------------------------
https://www.heise.de/news/OPNsense-Update-beseitigt-kritische-Rootluecke-un…
∗∗∗ HestiaCP Admin Takeover & RCE ∗∗∗
---------------------------------------------
A low privileged user in HestiaCP can exploit a Broken Authorisation flaw to takeover Admin accounts. [..] A patch can be found here. This currently needs to be applied manually until HestiaCP decide to create a release. CVE-2026-12196
---------------------------------------------
https://projectblack.io/blog/hestiacp-admin-takeover-rce/
∗∗∗ Dell: DSA-2026-278: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities ∗∗∗
---------------------------------------------
https://www.dell.com/support/kbdoc/de-de/000481268/dsa-2026-278-security-up…
∗∗∗ Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root ∗∗∗
---------------------------------------------
https://github.com/coollabsio/coolify/security/advisories/GHSA-chg4-63hm-xv…
∗∗∗ LWN: Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1081495/
∗∗∗ Roundcube: Security updates 1.6.17 and 1.7.2 released ∗∗∗
---------------------------------------------
https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 02-07-2026 18:00 − Freitag 03-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices ∗∗∗
---------------------------------------------
Google has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people's traffic.
---------------------------------------------
https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html
∗∗∗ Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials ∗∗∗
---------------------------------------------
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.
---------------------------------------------
https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.ht…
∗∗∗ Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer ∗∗∗
---------------------------------------------
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.
---------------------------------------------
https://thehackernews.com/2026/07/armored-likho-targets-government.html
∗∗∗ Indirect Prompt Injection in Web Content Targets AI Agents ∗∗∗
---------------------------------------------
AI agents are increasingly changing how users interact with web content, making the content itself a growing attack surface for threat actors. Just as a human user can be socially engineered through phishing, AI agents are also susceptible to similar attacks. Indirect prompt injection (IPI) is an example of these types of attacks that embed malicious instructions in the content retrieved by an AI agent (websites, documents, email, etc.) to influence the agent’s reasoning during task execution. Zscaler ThreatLabz has observed malicious websites that impersonate legitimate services and use IPI to manipulate AI-driven workflows.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-w…
∗∗∗ Fake Google and Cloudflare verification pages spread multiple malware families ∗∗∗
---------------------------------------------
ClickFix attacks, which trick people into running malicious commands themselves, continue to evolve. This latest campaign uses fake Google and Cloudflare verification pages to convince victims to infect their own devices.
---------------------------------------------
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-clou…
∗∗∗ The Gentlemen ransomware: what you need to know ∗∗∗
---------------------------------------------
Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. In little more than a year, The Gentlemen has gone from relative obscurity to becoming one of the most active ransomware operations on the planet. First surfacing in mid-2025, The Gentlemen is a ransomware-as-a-service (RaaS) operation that appears to have splintered away from the notorious Qilin ransomware group.
---------------------------------------------
https://www.fortra.com/blog/gentlemen-ransomware-what-you-need-know
∗∗∗ It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) ∗∗∗
---------------------------------------------
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working.
---------------------------------------------
https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusio…
∗∗∗ Mitglied im Sonderausschuss zu Pegasus: EU-Abgeordneter mit Spyware attackiert ∗∗∗
---------------------------------------------
Vor Jahren hat das Europaparlament Angriffe mit der Pegasus-Spyware in der EU untersucht. Ein stellvertretendes Ausschussmitglied wurde da selbst angegriffen.
---------------------------------------------
https://heise.de/-11352514
∗∗∗ How GitHub used secret scanning to reach inbox zero ∗∗∗
---------------------------------------------
GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here’s how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months.
---------------------------------------------
https://github.blog/security/application-security/how-github-used-secret-sc…
=====================
= Vulnerabilities =
=====================
∗∗∗ Behörde warnt: Microsoft-Sharepoint-Server werden attackiert ∗∗∗
---------------------------------------------
Angreifer nutzen eine gefährliche Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten handeln.
---------------------------------------------
https://www.golem.de/news/behoerde-warnt-microsoft-sharepoint-server-werden…
∗∗∗ Jetzt updaten: Kritische Lücken in Ubiquiti UniFi erlauben Remote-Angriffe ∗∗∗
---------------------------------------------
Mehrere Produkte aus Ubiquitis UniFi-Ökosystem sind von teils kritischen Lücken betroffen. Admins sollten die abgesicherten Versionen zügig einspielen.
---------------------------------------------
https://www.heise.de/news/Jetzt-updaten-Kritische-Luecken-in-Ubiquiti-UniFi…
∗∗∗ Angriff per USB-Stick: KI findet gefährliche Lücke in populärem FatFs-Treiber ∗∗∗
---------------------------------------------
Das bloße Anschließen eines USB-Sticks reicht aus, um auf vielen Embedded- und IoT-Geräten Schadcode einzuschleusen. Einen Patch gibt es bisher nicht. (Sicherheitslücke, Speichermedien)
---------------------------------------------
https://www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luec…
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1081187/
∗∗∗ NCSC-2026-0219 [1.00] [M/H] Kwetsbaarheden verholpen in GitHub Enterprise Server ∗∗∗
---------------------------------------------
https://advisories.ncsc.nl/advisory?id=NCSC-2026-0219
∗∗∗ NCSC-2026-0220 [1.00] [M/H] Kwetsbaarheden verholpen in Rancher door Rancher Labs ∗∗∗
---------------------------------------------
https://advisories.ncsc.nl/advisory?id=NCSC-2026-0220
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 01-07-2026 18:00 − Donnerstag 02-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Cisco finally confirms attackers exploiting Unified CM flaw ∗∗∗
---------------------------------------------
Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisco-finally-confirms-attac…
∗∗∗ 6 security settings every GitHub maintainer should enable this week ∗∗∗
---------------------------------------------
These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.
---------------------------------------------
https://github.blog/security/6-security-settings-every-github-maintainer-sh…
∗∗∗ Ransomware im Anmarsch: Hacker greifen mit fieser Interpol-Masche an ∗∗∗
---------------------------------------------
Angreifer geben sich bei Unternehmen als Personal von Interpol aus und ködern mit angeblichen Beweismitteln. Doch stattdessen gibt es Ransomware.
---------------------------------------------
https://www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-…
∗∗∗ Falsche Rechnungen und Chatpartner bei ZumDaten, MichVerlieben & Co. ∗∗∗
---------------------------------------------
Eine Rechnung über mehrere hundert Euro von einer Datingplattform, bei der Sie nie ein Konto angelegt haben? Genau das berichten derzeit zahlreiche Betroffene. Doch nicht nur Menschen, die sich nie angemeldet haben, geraten ins Visier: Auch Registrierte können durch fragwürdige Praktiken viel Geld verlieren. Was hinter den Maschen von michverlieben.com, zumdaten.com und Co. steckt – und wie Sie sich dagegen wehren können.
---------------------------------------------
https://www.watchlist-internet.at/news/falsche-zahlungsaufforderungen-von-d…
∗∗∗ New ChocoPoC malware targets researchers via trojanized PoC exploits ∗∗∗
---------------------------------------------
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets…
∗∗∗ Medtronic notifies customers impacted by ShinyHunters data breach ∗∗∗
---------------------------------------------
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers…
∗∗∗ Opera rolls out Paste Protect feature to fight ClickFix attacks ∗∗∗
---------------------------------------------
Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/opera-rolls-out-paste-protec…
∗∗∗ VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs.
---------------------------------------------
https://thehackernews.com/2026/07/veildrop-malware-chain-uses-blogger.html
∗∗∗ Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters ∗∗∗
---------------------------------------------
Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal network port. Synacktiv, which found the bug, says it can lead to a full cluster takeover. There is no fix and no CVE. The firm says it reported the flaw to Argo CD's maintainers in January 2025; roughly eighteen months later, it remains unpatched, so it published the details to warn users.
---------------------------------------------
https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html
∗∗∗ FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations ∗∗∗
---------------------------------------------
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.
---------------------------------------------
https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html
∗∗∗ Fehler in „E-Mail-Adresse verbergen“ von Apple weiter ohne Fix ∗∗∗
---------------------------------------------
„Hide my E-Mail“ oder „E-Mail-Adresse verbergen“ soll eigentlich User vor Spam und Co. schützen. Es gibt aber eine Lücke. Die Entdecker warten weiter auf Apple.
---------------------------------------------
https://heise.de/-11351055
∗∗∗ PamStealer: a Rust-based macOS infostealer that validates credentials through PAM ∗∗∗
---------------------------------------------
Jamf Threat Labs investigates PamStealer, a macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection.
---------------------------------------------
https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/
=====================
= Vulnerabilities =
=====================
∗∗∗ WinRAR flaw could allow attackers to take control of your computer ∗∗∗
---------------------------------------------
A new WinRAR update fixes a serious security flaw, but without automatic updates many users could miss the patch.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/07/winrar-flaw-could-allow-atta…
∗∗∗ Schwachstellen in Synology MailPlus Server lassen Angreifer passieren ∗∗∗
---------------------------------------------
Netzwerkspeicher von Synology mit MailPlus Server sind attackierbar. Ein Sicherheitspatch schafft Abhilfe.
---------------------------------------------
https://heise.de/-11351331
∗∗∗ ClamAV Vulnerabilities Affecting Cisco Products: July 2026 ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Catalyst Center Arbitrary File Read Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Drupal Security Advisories 2026-July-01 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ SVD-2026-0701: Third-Party Package Updates in Python for Scientific Computing - July 2026 ∗∗∗
---------------------------------------------
https://advisory.splunk.com//advisories/SVD-2026-0701
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1080956/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 30-06-2026 18:00 − Mittwoch 01-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) ∗∗∗
---------------------------------------------
For those that don’t start violently wretching when the phrase “Citrix NetScaler” is uttered, we have another word to whisper: “CitrixBleed”. As many know, the term CitrixBleed now refers to not a single vulnerability, but an entire class of Memory Disclosure-esque vulnerabilities in Citrix NetScaler devices, many of which have played roles in breaches and incidents in recent memory. [..] We’ve given up counting the numbers, and so we’ve decided to call this vulnerability “CitrixBleed To Infinity And Beyond”.
---------------------------------------------
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netsca…
∗∗∗ Over 900 Oracle E-Business instances exposed to ongoing attacks ∗∗∗
---------------------------------------------
Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-i…
∗∗∗ The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign ∗∗∗
---------------------------------------------
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.
---------------------------------------------
https://securelist.com/tr/the-soc-files-screenconnect-campaign-with-asyncra…
∗∗∗ Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data ∗∗∗
---------------------------------------------
New Microsoft research shows how attackers can hijack AI agents that act on a users behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire.
---------------------------------------------
https://thehackernews.com/2026/06/microsoft-warns-poisoned-mcp-tool.html
∗∗∗ RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS ∗∗∗
---------------------------------------------
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. [..] RustDuck does not lean on a single clever trick. It sprays a mix of old, well-known weaknesses and hopes one sticks. The first is the oldest in the book: devices left on the internet with weak or default passwords on their remote-login services (Telnet and SSH). Guess the password, walk in.
---------------------------------------------
https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html
∗∗∗ Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector ∗∗∗
---------------------------------------------
Unit 42 researchers found that large language models (LLMs) consistently hallucinate web domains for legitimate brands. Adversaries are actively weaponizing this vector by registering these nonexistent domains to intercept traffic generated by AI systems. We call this phenomenon phantom squatting, and it poses a significant risk to the software supply chain.
---------------------------------------------
https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-doma…
∗∗∗ ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 ∗∗∗
---------------------------------------------
Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026.
---------------------------------------------
https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-p…
∗∗∗ Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique ∗∗∗
---------------------------------------------
In this research, DeepSeek connected unrealistic browser-malware concepts with a real browser capability, turning an AI-generated malware hallucination into a plausible browser-native ransomware technique. Although the generated sample was incomplete, it exposed a practical abuse path based on the File System Access API and access to photo directories.
---------------------------------------------
https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallu…
=====================
= Vulnerabilities =
=====================
∗∗∗ Adobe patches seven max severity ColdFusion, Campaign flaws ∗∗∗
---------------------------------------------
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-seve…
∗∗∗ Riesiges Update: 382 Sicherheitslücken in Google Chrome entdeckt ∗∗∗
---------------------------------------------
Die neueste Chrome-Version schließt fast 400 teils kritische Sicherheitslücken. Auch für Edge, Vivaldi und Brave dürften entsprechende Updates folgen.
---------------------------------------------
https://www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-…
∗∗∗ Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service ∗∗∗
---------------------------------------------
Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. CVE-2026-8451 (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP.
---------------------------------------------
https://thehackernews.com/2026/07/citrix-patches-six-netscaler-flaws.html
∗∗∗ Root-Sicherheitslücken in alternativer Router-Firmware OpenWRT geschlossen ∗∗∗
---------------------------------------------
Die OpenWRT-Entwickler haben in einer aktuellen Version unter anderem mehrere kritische Sicherheitslücken geschlossen. [..] Am gefährlichsten gilt eine „kritische“ Lücke mit einem CVSSS Score 9.9 von 10 in LuCI. Eine CVE-Nummer wurde offensichtlich bislang nicht vergeben. Voraussetzung für eine Attacke ist, dass der VPN-Dienst Tailscale installiert ist.
---------------------------------------------
https://www.heise.de/news/Root-Sicherheitsluecken-in-alternativer-Router-Fi…
∗∗∗ HCL BigFix: PC-Fernverwaltung: Man-in-the-Middle-Attacken auf HCL BigFix möglich ∗∗∗
---------------------------------------------
https://www.heise.de/news/PC-Fernverwaltung-Man-in-the-Middle-Attacken-auf-…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1080689/
∗∗∗ mozilla: Security Vulnerabilities fixed in Thunderbird 140.12.1 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/
∗∗∗ mozilla: Security Vulnerabilities fixed in Thunderbird 152.0.1 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-63/
∗∗∗ Genucenter: Publish SBA-ADV-20260424-01: Genucenter Disclosure of SNMP Credentials ∗∗∗
---------------------------------------------
https://github.com/sbaresearch/advisories/commit/d78bf80a4103af68e8c17ba027…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/